Teatimecreams Posted April 17, 2005 Author Report Share Posted April 17, 2005 Right then....Im going to sign off....disconnect....Disable the ethernet adaptor....Restart the poota in safe mode...Run the doc.exe...Then try and re-install in safe modeThanks to Nellie as well.. \oBe back in 10 hopefully... :blink: x Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 17, 2005 Report Share Posted April 17, 2005 I notice that you are back online. Did it work then? Quote Link to comment Share on other sites More sharing options...
Teatimecreams Posted April 17, 2005 Author Report Share Posted April 17, 2005 :wallbash: Argggggggggggghhhhhhhhhhhhhhhhhhhhhhno joy....the very same thing happens..... :( Quote Link to comment Share on other sites More sharing options...
Teatimecreams Posted April 17, 2005 Author Report Share Posted April 17, 2005 Ermmmmmmmmm just a thought Curly...i use aol's computer check up....this finds spyware...Do u suggest i d.load my own spybot or ad-aware?x Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 17, 2005 Report Share Posted April 17, 2005 I can't help you anymore as I never had that much trouble installing my broadband drivers :blink: I would contact AOL again and insist that if they can't help you, then you will cancel the contract and move to another ISP? Just a thought, are you sure that you have no spyware on your PC as if you had a dialler on there (perish the thought), then this could be stopping the modem from installing and changing the default settings? :unsure: Just a thought though. Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 17, 2005 Report Share Posted April 17, 2005 Ermmmmmmmmm just a thought Curly...i use aol's computer check up....this finds spyware...Do u suggest i d.load my own spybot or ad-aware?xSorry to disagree, but AOL's Computer check-up fixes browser and internet connectivity problems and does not search for spyware. I would definently download Spybot and Ad-Aware and run them as when I first had a PC, I didn't use anti-spyware tools either and my PC was inundated with spyware. This may be the problem! :unsure: Quote Link to comment Share on other sites More sharing options...
Teatimecreams Posted April 17, 2005 Author Report Share Posted April 17, 2005 Ok......i'll trot off and sort this out...do u suggest d/loading either or both...and are they freeware?(jeez...u must be sick to death of me :flowers: )x Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 17, 2005 Report Share Posted April 17, 2005 Both are free and I have been using them for over 3 years now with no problems at all. If any spyware is found you may consider downloading SpyWareblaster which stops spyware getting on your PC in the first place from Click here Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 17, 2005 Report Share Posted April 17, 2005 Perhaps you should also post a HiJack this log from Click hereThere are also instructions from the link. Then one of our Spyware Specialists will be able to analyse it for you ;) Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 17, 2005 Report Share Posted April 17, 2005 Teatimecreams, did you have any spyware on your PC after running Spybot and Ad-Aware? Quote Link to comment Share on other sites More sharing options...
Teatimecreams Posted April 18, 2005 Author Report Share Posted April 18, 2005 Good Mawnin Curly...Ran the spybot prog.....ermmmm 114 problems found...(is that bad?)... :blink:It has left the following screenshot that havent been 'fixed'.... (tried a reinstall afterwards....to no avail)....and the beat goes on........(sigh)x Quote Link to comment Share on other sites More sharing options...
Teatimecreams Posted April 18, 2005 Author Report Share Posted April 18, 2005 Oh gosh this is fun...I'm sending a s/shot of my i/connections....which all say 'disconnected' and the ethernet adaptor 'disabled'...Then how the frigging hell am i online....?(chuckle)x :D Quote Link to comment Share on other sites More sharing options...
Teatimecreams Posted April 18, 2005 Author Report Share Posted April 18, 2005 BTW...The link to the hijack this ..Please see instructions HERE for instructions on using and posting your HijackThis! log." Well its broken...so no go on that either.... :unsure: x Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted April 18, 2005 Report Share Posted April 18, 2005 The instructions are here.Then how the frigging hell am i online....?(chuckle)Maybe through the LAN ? Quote Link to comment Share on other sites More sharing options...
Teatimecreams Posted April 18, 2005 Author Report Share Posted April 18, 2005 Logfile of HijackThis v1.99.1Scan saved at 10:29:27, on 18/04/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\AOL\ACS\AOLAcsd.exeC:\Program Files\Norton AntiVirus\SAVScan.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\SOUNDMAN.EXEC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\gam.exeC:\Program Files\Zauxsvy\Mctyg.exeC:\Program Files\Common Files\AOL\ACS\AOLDial.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Real\RealPlayer\RealPlay.exeC:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exeC:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exeC:\Program Files\AOL 9.0a\aoltray.exeC:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exeC:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exeC:\PENSOFT\fquick32.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\AOL\Broadband CheckUp\bin\mpbtn.exeC:\Program Files\AOL Companion\companion.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\wuauclt.exeC:\WINDOWS\System32\wuauclt.exeC:\WINDOWS\SoftwareDistribution\Download\3ab3c750096febe50fc47ce46ea0b9dc\update\update.exeC:\Program Files\AOL 9.0a\waol.exeC:\Program Files\AOL 9.0a\shellmon.exeC:\Program Files\Common Files\AOL\aoltpspd.exeC:\Documents and Settings\sam\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blankR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.timecomputers.comO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dllO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXEO4 - HKLM\..\Run: [supaDial] C:\Program Files\SupaDial\SupaDial.exe /AO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [Windows Media Player] msa.exeO4 - HKLM\..\Run: [Windows SSL File] winssv.exeO4 - HKLM\..\Run: [uSBHWDRV] C:\gam.exeO4 - HKLM\..\Run: [uSBHWINFO] C:\sst6.exeO4 - HKLM\..\Run: [Microsofts media] winmplayd.exeO4 - HKLM\..\Run: [NvCplScan] msc32.exeO4 - HKLM\..\Run: [fwfghaz] C:\WINDOWS\fwfghaz.exeO4 - HKLM\..\Run: [bearShare] "C:\Program Files\BearShare\BearShare.exe" /pauseO4 - HKLM\..\Run: [N4uL] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exeO4 - HKLM\..\Run: [¢‰¸u0–4C}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [¢‰¸u0Ô@ÔÁß]ú"ü‰üžiC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [Ebjbfo] C:\Program Files\Zauxsvy\Mctyg.exeO4 - HKLM\..\Run: [¢‰¸u0Ô@ÔÁß]ú"ü‰¸u0C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [¢‰¸u0ÔÁß]ú"ü‰üžigÝC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYERO4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exeO4 - HKLM\..\RunServices: [Windows Media Player] msa.exeO4 - HKLM\..\RunServices: [Windows SSL File] winssv.exeO4 - HKLM\..\RunServices: [Microsofts media] winmplayd.exeO4 - HKLM\..\RunServices: [NvCplScan] msc32.exeO4 - HKCU\..\Run: [Windows SSL File] winssv.exeO4 - HKCU\..\Run: [Windows Media Player] msa.exeO4 - HKCU\..\Run: [NvCplScan] msc32.exeO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /backgroundO4 - Startup: Quick StartUp.lnk = C:\PENSOFT\fquick32.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0a\aoltray.exeO4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exeO4 - Global Startup: AOL Broadband Check-Up.lnk = C:\Program Files\AOL\Broadband CheckUp\bin\matcli.exeO4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exeO4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exeO8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTMLO9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dllO9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dllO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXEO14 - IERESET.INF: START_PAGE_URL=http://www.timecomputers.comO16 - DPF: {00000000-0000-0000-0000-000020040000} - http://207.234.185.217/ABoxInst_int4.exeO16 - DPF: {0ED74E87-6693-2E44-2E33-5121669B6BC9} - http://66.117.37.5/1/rdgGB298.exeO16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1112132257171O17 - HKLM\System\CCS\Services\Tcpip\..\{ED3D575B-15BF-488A-8EAC-E9600EE40074}: NameServer = 205.188.146.145O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exeO23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe Quote Link to comment Share on other sites More sharing options...
nellie2 Posted April 18, 2005 Report Share Posted April 18, 2005 I'm afraid you have a few problems there... I don't know if they are related to your connection problems but we need to get you cleaned up.BearShare isn't a good choice for a p2p program and I recommend you uninstall it. This article is a bit old now but the information there is still valid. See here for spyware free alternativesYou are running hijackthis from a temporary directory and from inside the zip. please move HijackThis into a permanent folder. It is important that you run HijackThis.exe in its own folder so the backup files that HijackThis file will create will not be accidentally deleted on reboot. Open 'My Computer', then double-click to open C:\ (or the drive letter that your Windows is installed) In the menu bar, click File-->New-->Folder. That will create a folder named New Folder, which you can rename to "HJT" or "HijackThis". Now you have C:\HJT\ or C:\HijackThis\ folder. Put your HijackThis.exe there.Run hijackthis and click the scan button, when it has finished scanning then put a tick against the following, close all other browsers and windows and click 'fix checked'R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blankO4 - HKLM\..\Run: [Windows Media Player] msa.exeO4 - HKLM\..\Run: [Windows SSL File] winssv.exeO4 - HKLM\..\Run: [uSBHWDRV] C:\gam.exeO4 - HKLM\..\Run: [uSBHWINFO] C:\sst6.exeO4 - HKLM\..\Run: [Microsofts media] winmplayd.exeO4 - HKLM\..\Run: [NvCplScan] msc32.exeO4 - HKLM\..\Run: [fwfghaz] C:\WINDOWS\fwfghaz.exeO4 - HKLM\..\Run: [N4uL] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [¢‰¸u0–4C}ïÁzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [¢‰¸u0Ô@ÔÁß]ú"ü‰üžiC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [Ebjbfo] C:\Program Files\Zauxsvy\Mctyg.exeO4 - HKLM\..\Run: [¢‰¸u0Ô@ÔÁß]ú"ü‰¸u0C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\elxaro.exeO4 - HKLM\..\Run: [¢‰¸u0ÔÁß]ú"ü‰üžigÝC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\elxaro.exeO4 - HKLM\..\RunServices: [Windows Media Player] msa.exeO4 - HKLM\..\RunServices: [Windows SSL File] winssv.exeO4 - HKLM\..\RunServices: [Microsofts media] winmplayd.exeO4 - HKLM\..\RunServices: [NvCplScan] msc32.exeO4 - HKCU\..\Run: [Windows SSL File] winssv.exeO4 - HKCU\..\Run: [Windows Media Player] msa.exeO4 - HKCU\..\Run: [NvCplScan] msc32.exeO16 - DPF: {00000000-0000-0000-0000-000020040000} - http://207.234.185.217/ABoxInst_int4.exeThen reboot into safe mode, you may have to enable hidden files and folders and delete the followingC:\gam.exeC:\sst6.exeC:\WINDOWS\fwfghaz.exe C:\WINDOWS\elxaro.exeC:\Program Files\ISTsvc\istsvc.exeC:\WINDOWS\elxaro.exeYou will also need to use the Windows Search facility to find and delete these filesmsa.exewinssv.exe winmplayd.exemsc32.exeWhen done then reboot and post a fresh log pleae Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 22, 2005 Report Share Posted April 22, 2005 Did you follow Nellie2's instructions? Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.